Site navigation

Is Third-Party Risk Now the Weakest Link in Cybersecurity?

Elizabeth Greenberg

,

third-party risk management
In this interview with DIGIT, Kapish Vanaria, EY’s Global and Americas Risk Consulting Leader, provides context and advice in managing risk in an increasingly complex third-party vendor landscape.

From hyper-scalers to startups, third-party suppliers are now integral to the global business ecosystem – but as they multiply and entrench, the inevitable software sprawl expands the attack surface organisations must defend.   

Third party risk management is of growing importance to cyber leaders and organisational boards as supply chain complexity expands. 

With the vast majority (93%) of firms relying on third-party services to deliver their core value propositions, ensuring these vendors are secure is of increasing importance. 

Companies no longer work with just third parties, but fourth, fifth, and sixth, all bringing their own cyber vulnerabilities and risks. 

With third-party risks accounting for nearly a third (31%) of client insurance claims according to research from Resilience, the need for reform in third-party risk management seems more pertinent than ever. 

While JP Morgan’s CISO Patrick Opet calls on third-party vendors themselves to employ a “secure and resilience by design” protocol, Gartner points out that risk managers are often not reliably communicating red flags they see in their third party partners. 

Beyond this, a recent cybersecurity report from EY shows that risk management programmes are managing more and more third parties. The research claims that programs under three years old manage a median of 275 third parties, while older ones manage a median of 80. 

The report found that these numbers are expanding: in just the past year, the number of third parties being leveraged increased by an average of 20% across all types of organisations. 

High-profile third-party risk cases, namely the Crowdstrike outage that interrupted Microsoft systems relied upon by major airlines and other industries, brought these risks to the forefront.

As businesses continue to scramble to integrate the latest tech and scale their operations, the problem isn’t going to go away any time soon.

So what can be done?

To answer that, DIGIT spoke with Kapish Vanvaria, EY’s Global and Americas Risk Consulting Leader, to get a better understanding of third party vulnerabilities and how to manage them. 

A Sign of the Times

The supply chain is getting more complicated, but this is just a symptom of a transforming world, Vanvaria said. 

“Technology is moving so fast and organisations are always under pressure to grow and provide shareholder value,” Vanvaria said. 

“There’s a natural reliance on others, a strength in numbers to be successful.”

But as the number of vendors and supply chain partners increase, this strength can turn into risky business if the proper protocols are not taken into account.

Third parties are not just valuable assets, but are often unavoidable as organisations pivot their  digital transformation priorities, create new products or expand into new markets. 

These suppliers are not necessarily worse at cybersecurity. 

“All those organisations are likely fantastic on their own,” Vanvaria said of third party suppliers. “In silos, they’re all excellent.”

This is where operational resilience comes into play, as managing this complex ecosystem, which increases risk by default, is where true resilience can be built. 

“Its not just monitoring third parties, but understanding your concentration of risk when they’re all combined,” Vanvaria said. 

Understanding the underlying supply chain associated with each third party, their relationship with each other, and how wider influences – geopolitical tensions, economic turbulence – may affect them, is vital in making education risk decisions. 

But this complexity does make third party auditing more complicated – what once was a “manual exercise” is now a complicated balancing act of various data points, a deep understanding of global supply chain stability, and the financial stability of the company. 

“To do that level of depth of assessment on a human basis using legacy technology is very difficult, because not only are you dealing with that volume of information, but it is very hard to decipher.” 

The Five Resiliencies 

Adding onto this complexity for organisations to manage themselves and audit others, are the five types of resiliency Vanvaria categorised. 

First is technology resiliency, which would include having the right tech and tools to maintain a high level of security to prevent attacks. 

Operational resiliency is where things collide – security silos can be deadly, communication between departments becomes key, and an indepth understanding of the interplay between different third-parties is vital. 

Human capital resilience is related to the skills gap and talent crisis, being able to attract and retain the right people, a growing issue as the cyber skills gap only grows as attacks increase in sophistication. 

Supply chain resiliency can be tied into economic stresses, economic strain and global recessions. 

This ties in closely with geopolitical resiliency as tensions rise, but also as regulations change in different markets. 

Juggling all of these is vital in assessing an organisation’s overall resilience, as well as its cybersecurity posture. 

With all of these compounding factors, what can risk managers do differently to not succumb to these third party vulnerabilities? 

Designing Your Operational Resilience

Get Managers Involved Early

First of all, risk managers should be brought into the process earlier. 

Most organisations are very familiar with the second and third lines of defence – compliance risks and exhaust functions – but few industries employ a first line of defence unless mandated to. 

Relegating a risk manager to the second or third lines of defence – after a third-party is signed on or after a new technology is adopted – can lead to a disconnect or a function of “pumping the brakes” on vital innovation. 

“Right now, the risk manager should be the first line of defence in line with business stakeholders. They shouldn’t be brakes to slow the car down, but  brakes to allow organisations to go faster, and help them turn corners safely,” Vanvaria said. 

Once risk managers are brought in earlier, then they can take the reigns.

Unconstrained Thinking

Vanvaria encourages “unconstrainted thinking” to design an ideal third party valuation programme. 

“If you could design that third party valuation programme of that vendor or your organisation with no limitations, no politics, no system limitations, no technology limitations, what would that be?”

Thinking ideally and without limitations can allow organisations to reevaluate existing systems to align them with company values, and can then be worked with with limitations. 

“Do not shy away from redesigning your third party risk programme to account for the dynamic nature of risks changing,” Vanvaria said, harkening back to the five resilience categories he mentioned. 

“Traditional third-party risk frameworks were built for a static world, but today’s threat landscape shifts with unprecedented velocity — from overnight regulatory changes to geopolitical tensions that can instantly transform a trusted vendor into a compliance liability. 

“Organisations must move beyond annual risk assessments in favour of continuous, quarterly evaluations that capture emerging risks such as supply chain nationalism, regulatory arbitrage, and cascading cyber threats. The most resilient companies build agility into their risk architecture, treating third-party management as a dynamic capability rather than a compliance checkbox.”


Recommended reading


Leveraging New Technologies

Part of this redesign should be to leverage new technologies, particularly AI, as part of the third party auditing process. 

“You can leverage AI technology to do these evaluations and come back with a much stronger point of view,” Vanvaria said. 

Using advanced technologies and AI systems to help audit third parties across not just their security posture, but their financial reports and other signs of company health, can help organisations make a more calculated risk decision. 

“The future of third-party risk management lies in shifting from reactive compliance to predictive intelligence — where AI doesn’t just automate processes but reimagines how risk is identified and assessed,” Vanvaria said. 

“Organisations should use machine learning to synthesize vast datasets — from financial performance and cyber ratings to ESG metrics and geopolitical indicators — creating a real-time intelligence layer that surfaces threats before they materialize. 

“The competitive edge belongs to firms that can transform their third-party ecosystems from cost centers into strategic intelligence networks.” 

AI tools can help organisations make educated decisions around organisational risks ranging across the five resilience types Vanvaria mentioned. 

While it is impossible to take no risk, this can give organisations a better overall understanding when forming relationships with third parties. 

These technologies can also allow risk managers to focus on another key part of mitigating vulnerabilities, which is building stronger relationships with partners. 

Strengthen Relationships Through Communication

Vanaria said the companies that weathered Covid most effectively were those with strong vertical integration – either owning their entire supply chain or maintaining tightly controlled relationships with third parties and partners.

While this is not necessarily possible for many organisations, there’s insights to be extrapolated. 

Having closer relationships with third-parties can be vital in reducing risk, understanding their inherent vulnerabilities, and mitigating these threats from the start. 

As Gartner pointed out, communication is now a major factor in third-party relationship management. 

Vanvaira wants organisations to take this a step further, however, and talk to each other. 

Plugging into a peer network to discuss current events, geopolitical tensions, and different organisational structures can be key in nurturing a more unconstrained viewpoint in operational resiliency. 

“In today’s evolving third-party risk landscape, isolation is a strategic vulnerability,” Vanvaria said.

“The most effective risk leaders actively participate in industry roundtables and peer networks to stay ahead of emerging trends and proven response strategies. 

“These forums offer invaluable insight into how leading organizations are adapting their frameworks for new challenges like AI governance, ESG compliance, and supply chain resilience — while also sharing real-world case studies of what works (and what doesn’t). 

“The collective intelligence gained often reveals blind spots and accelerates the adoption of next-generation risk management practices that would take years to build independently.”

Communication appears to be key throughout an organisation and its wider supply chain. While risks cannot be avoided completely, these tools can be key in managing risks, making educated vendor selection, and ultimately protecting organisations more fully in an increasingly dangerous cyber landscape. 

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data